{
  "data": {
    "a": {
      "slug": "devin",
      "name": "Devin",
      "vendor": "Cognition AI, Inc.",
      "vendorUrl": "https://devin.ai",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Devin is Cognition's hosted coding agent. It works in its own cloud virtual machine to plan, edit code, run commands and open pull requests. Outside agents start and steer sessions through a REST API and a remote MCP server.",
      "url": "https://www.anchorterminal.com/tools/devin",
      "markdownUrl": "https://www.anchorterminal.com/tools/devin.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/devin.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/devin.json",
      "license": "Proprietary service under Cognition's Platform Terms of Service",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://mcp.devin.ai/mcp",
      "packages": [],
      "auth": "api-key",
      "authNotes": "A Bearer token with the `cog_` prefix on every request to https://api.devin.ai/v3. Service-user keys are provisioned by a person in Settings \u003e Devin API, shown once, and carry a role (Admin or Member on Teams, custom roles on Enterprise). Personal access tokens act as the user who made them and can expire. Legacy `apk_` keys work only with the deprecated v1 and v2 APIs. The MCP server takes the same keys, and enterprise keys and personal tokens add an `X-Org-Id` header. Access is self-serve, with no app review or sales approval for Teams.",
      "pricing": "freemium",
      "pricingNotes": "Free $0, Pro $20 a month, Max $200 a month, Teams $80 a month minimum with full seats at $40 each, Enterprise by quote (devin.ai/pricing, checked 2026-10-08). Paid plans include a daily or weekly usage quota, then prepaid on-demand credits described as usage at API pricing, with no unit rate on the page. The pricing page lists cloud agents from Pro upward, while the docs say Free includes limited Devin usage. Whether the API works on Free, and whether signup needs a card, wasn't established.",
      "priceSummary": "$20 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the v3 OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 13,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.devin.ai",
      "llmsTxt": "https://docs.devin.ai/llms.txt",
      "openapi": "https://docs.devin.ai/v3-openapi.yaml",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "hosted",
        "cloud-agent",
        "closed-source",
        "api-key",
        "rbac",
        "openapi",
        "llms-txt",
        "mcp",
        "status-page",
        "soc2",
        "freemium"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.7,
        "grade": "C",
        "agentReady": false,
        "rank": 447,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 15,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 63,
          "payments": 20,
          "reliability": 30,
          "schema": 80,
          "security": 72,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.",
        "bestFor": "A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.",
        "strengths": [
          "Public OpenAPI 3.1 spec for the v3 API with 239 operations, each declaring 401, 403, 404, 409, 422 and 429 responses in RFC 9457 problem+json",
          "Service-user keys carry a role, every endpoint except GET /v3/self names the permission it needs, and audit logs list service users separately from people",
          "Security profiles can limit a session to a network allowlist, an MCP server allowlist, read-only git and a read-only Devin MCP",
          "Remote MCP server at mcp.devin.ai/mcp with 13 documented tools for sessions, playbooks, knowledge, schedules and repository documentation",
          "Dated release notes several times a week, the newest on 7 October 2026, and a separate API release notes page"
        ],
        "weaknesses": [
          "www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026",
          "No rate limit figures, Retry-After or backoff guidance found in the API docs, and v3 session creation has no idempotency key",
          "Customer data may be used for model training by default on self-serve plans. The opt-out is for paid plans only, per section 3.3.1 of the platform terms",
          "A person must sign up and provision the service user in the web app. No key-creation route exists for an agent starting from nothing",
          "No official SDK found, and the Devin MCP server was not found in the official MCP registry"
        ],
        "agentNotes": [
          "Use a `cog_` service-user key with the Member role. Legacy `apk_` keys fail against v3 and the MCP server with 401 or 403",
          "Set `max_acu_limit` on every session you create. Usage is metered by the work done and has no published unit rate",
          "Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again",
          "Enterprise keys and personal access tokens must send `X-Org-Id` to the MCP server. Organisation-scoped keys resolve it automatically",
          "Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.7
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 63,
          "payments": 20,
          "reliability": 30,
          "schema": 80,
          "security": 72,
          "transparency": 61
        },
        "provenanceScore": 77
      },
      "connect": {
        "http": "curl -X POST \"https://api.devin.ai/v3/organizations/$DEVIN_ORG_ID/sessions\" -H \"Authorization: Bearer $DEVIN_API_KEY\" -H \"Content-Type: application/json\" -d '{\"prompt\": \"Create a simple Python script that prints Hello World\"}'",
        "config": {
          "mcpServers": {
            "devin": {
              "headers": {
                "Authorization": "Bearer \u003cAPI_KEY\u003e",
                "X-Org-Id": "\u003cYOUR_ORG_ID\u003e"
              },
              "serverUrl": "https://mcp.devin.ai/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/devin"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 20,
          "note": "one user, daily and weekly usage quota"
        },
        {
          "item": "Max plan",
          "unit": "month",
          "usd": 200,
          "note": "one user, larger weekly quota"
        },
        {
          "item": "Teams full seat",
          "unit": "seat-month",
          "usd": 40,
          "note": "$80 a month minimum per team, flex seats free and billed from shared credits"
        }
      ],
      "provenance": {
        "legalEntity": "Cognition AI, Inc.",
        "domain": "devin.ai",
        "domainRegistered": "2022-12-06",
        "endpointOnVendorDomain": true,
        "terms": "https://cognition.com/legal/platform-terms-of-service",
        "privacy": "https://cognition.com/legal/privacy-policy",
        "statusPage": "https://www.devinstatus.com",
        "changelog": "https://docs.devin.ai/release-notes/overview",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Platform Terms of Service (last updated 30 June 2026) name Cognition AI, Inc. and govern the Cognition Platform for customers who register and use the services. Enterprise customers sign separate Enterprise Terms of Service.",
          "The privacy policy (last updated 9 March 2026) names Cognition AI, Inc and covers Devin and Windsurf as well as cognition.com. The data processing agreement gives the address 550 Third Street, San Francisco, CA 94107.",
          "devin.ai, cognition.com and api.devin.ai all return 404 for /.well-known/security.txt. The docs give security@cognition.ai for vulnerability reports.",
          "The API answers at api.devin.ai and the MCP server at mcp.devin.ai. status.devin.ai redirects to www.devinstatus.com.",
          "RDAP for devin.ai gives a registration date of 2022-12-06."
        ],
        "score": 77
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/devin.json",
      "live": {
        "slug": "devin",
        "probe": {
          "target": "https://mcp.devin.ai/mcp",
          "method": "get",
          "lastAt": "2026-10-08T19:08:45.013833265Z",
          "lastOk": true,
          "lastStatus": 406,
          "lastMs": 426,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 450,
          "p95ms24h": 579,
          "samples24h": 19,
          "samples30d": 19,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 19,
              "ok": 19
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.devinstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:34.332954915Z"
        },
        "pages": [
          {
            "url": "https://docs.devin.ai/release-notes/overview",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:39.860758812Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a85f82787c20"
          },
          {
            "url": "https://cognition.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:28.045423959Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0ab177a921b1"
          },
          {
            "url": "https://cognition.com/legal/platform-terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:26.004141328Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e794136b2fe5"
          }
        ],
        "updatedAt": "2026-10-08T19:08:45.013833265Z"
      }
    },
    "answer": "Paperclip scores 59 (C) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth.",
    "b": {
      "slug": "paperclip",
      "name": "Paperclip",
      "vendor": "Paperclip Labs, Inc.",
      "vendorUrl": "https://paperclip.ing",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Paperclip is an open-source, self-hosted server and web interface that organises AI agents into a company with an org chart, tasks, budgets and approvals. It drives Claude Code, Codex, OpenClaw and other harnesses through adapters.",
      "url": "https://www.anchorterminal.com/tools/paperclip",
      "markdownUrl": "https://www.anchorterminal.com/tools/paperclip.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paperclip.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paperclip.json",
      "repo": "https://github.com/paperclipai/paperclip",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "paperclipai"
        },
        {
          "registry": "npm",
          "name": "@paperclipai/mcp-server"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/paperclipai/paperclip"
        }
      ],
      "auth": "mixed",
      "authNotes": "No Paperclip account. The default `local_trusted` mode needs no login on loopback. Authenticated mode uses browser sessions for people, board API keys for scripts, and agent API keys or short-lived run JWTs as bearer tokens.",
      "pricing": "free",
      "pricingNotes": "Free and MIT, self-hosted, with nothing to buy. The owner pays each harness's model provider or subscription. Paperclip Cloud is a waitlist with no published price.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the site or the server source (checked 2026-10-08). The only mention in the repository is a link to a third-party skill in a planning note.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 98666,
        "npmWeekly": 59684,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.paperclip.ing",
      "llmsTxt": "https://paperclip.ing/llms.txt",
      "capabilities": [
        "agent.multi-agent",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "free",
        "no-card",
        "llms-txt",
        "docker",
        "mcp",
        "typescript"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59,
        "grade": "C",
        "agentReady": false,
        "rank": 390,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 78,
          "payments": 60,
          "reliability": 66,
          "schema": 81,
          "security": 64,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -10,
        "negativeNotes": [
          "2026-04-10 to 2026-04-16. Ten advisories published in a week, four of them critical, among them GHSA-68qg-g8mg-6pr7 (CVE-2026-41679, 10.0, unauthenticated remote code execution through an import authorisation bypass) and two cross-tenant agent key flaws rated 9.9. All ten list 2026.416.0 as the fix. Fixed and published, a little under six months old, -5. https://github.com/paperclipai/paperclip/security/advisories",
          "2026-07-22. GHSA-x8hx-rhr2-9rf7 (9.6), drive-by remote code execution against the default `local_trusted` mode through DNS rebinding. The advisory names no patched version. The current source applies the hostname guard to `local_trusted` private deployments, so we read it as fixed without a documented version, -3. https://github.com/paperclipai/paperclip/security/advisories/GHSA-x8hx-rhr2-9rf7",
          "2026-04-16. GHSA-gqqj-85qm-8qhf (8.7), a `codex_local` agent inherited a Gmail connector from the owner's ChatGPT account and sent real email. The advisory names no patched version, and `codex_local` still defaults to bypassing approvals and the sandbox, -2. https://github.com/paperclipai/paperclip/security/advisories/GHSA-gqqj-85qm-8qhf"
        ],
        "verdict": "Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.",
        "bestFor": "Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.",
        "strengths": [
          "One deployment runs agents on Claude Code, Codex, Cursor, Gemini CLI, OpenCode, Pi, Hermes, Grok Build, Kimi Code and OpenClaw through adapters, under one org chart",
          "Board approvals gate agent hires and the CEO agent's strategy, and connection actions can be set to Allowed, Ask first or Off",
          "Budgets by company, agent and project pause an agent at 100 per cent of recorded spend",
          "The running server publishes its REST surface as OpenAPI at `/api/openapi.json`, and the docs site answers every page as Markdown at `.md`",
          "Eleven stable releases between 20 July and 5 October 2026, each with dated notes and an upgrade guide"
        ],
        "weaknesses": [
          "`claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host",
          "Twelve published security advisories since April 2026, five critical, including CVE-2026-41679 (unauthenticated remote code execution, fixed in 2026.416.0)",
          "Anonymous usage telemetry is on by default and goes to telemetry.paperclip.ing until an opt-out is set",
          "2,849 open issues on 8 October 2026, 1,396 of them with no comment, and 78 closed in 30 days against 686 opened",
          "Calendar versions with no 1.0, and release 2026.916.0 carried five breaking changes"
        ],
        "agentNotes": [
          "Set `PAPERCLIP_TELEMETRY_DISABLED=1` or `DO_NOT_TRACK=1` before the first start. Telemetry is on by default",
          "Set `dangerouslySkipPermissions` and `dangerouslyBypassApprovalsAndSandbox` to false on agents that read untrusted input, or run them in a sandbox provider",
          "Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there",
          "Use `--bind lan` or `--bind tailnet` at onboarding for anything beyond one machine. The default `local_trusted` mode treats every request as the board admin",
          "Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 78,
          "payments": 60,
          "reliability": 66,
          "schema": 81,
          "security": 64,
          "transparency": 73
        },
        "provenanceScore": 56
      },
      "connect": {
        "install": "npx paperclipai@latest onboard --yes   # Node.js 24.11 or newer",
        "http": "curl http://localhost:3100/api/health",
        "headless": {
          "command": "npx paperclipai issue create --title \"$TASK\" --json",
          "env": {
            "PAPERCLIP_API_KEY": "\u003cboard or agent key\u003e",
            "PAPERCLIP_TELEMETRY_DISABLED": "1"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.multi-agent",
        "tool": "https://letme.dev/paperclip"
      },
      "area": "frameworks",
      "provenance": {
        "legalEntity": "Paperclip Labs, Inc.",
        "domain": "paperclip.ing",
        "domainRegistered": "2026-03-02",
        "endpointOnVendorDomain": null,
        "terms": "https://paperclip.ing/terms/",
        "privacy": "https://paperclip.ing/privacy/",
        "statusPage": "",
        "changelog": "https://paperclip.ing/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms (effective 1 April 2026, updated 23 July 2026) and the privacy policy (effective 23 July 2026) name Paperclip Labs, Inc. and Delaware law. The licence file in the repository reads Copyright (c) 2025 Paperclip AI.",
          "RDAP at the .ing registry gives a registration date of 2026-03-02 for paperclip.ing, with Cloudflare as registrar. The GitHub repository was created the same day.",
          "paperclip.ing/.well-known/security.txt and docs.paperclip.ing/.well-known/security.txt returned 404 on 8 October 2026. SECURITY.md sends reports to GitHub private advisories.",
          "The software is self-hosted, so there is no vendor endpoint or status page to check. status.paperclip.ing did not answer.",
          "The privacy policy says it governs the hosted services, and that a self-hosted deployment processes data on the owner's infrastructure."
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/paperclip.json",
      "live": {
        "slug": "paperclip",
        "versions": [
          {
            "registry": "github",
            "name": "paperclipai/paperclip",
            "version": "v2026.1005.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:24:44.149648743Z"
          },
          {
            "registry": "npm",
            "name": "@paperclipai/mcp-server",
            "version": "2026.1005.0",
            "seenAt": "2026-10-08T16:24:42.049344463Z"
          },
          {
            "registry": "npm",
            "name": "paperclipai",
            "version": "2026.1005.0",
            "seenAt": "2026-10-08T16:24:41.941235603Z"
          }
        ],
        "githubStars": 98744,
        "npmWeekly": 59684,
        "securityTxt": {
          "url": "https://paperclip.ing/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:09.089543926Z"
        },
        "pages": [
          {
            "url": "https://paperclip.ing/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:47.072089969Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4d68b2d18041"
          },
          {
            "url": "https://paperclip.ing/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:49.382016209Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d75ac8f8733e"
          },
          {
            "url": "https://paperclip.ing/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:51.246933771Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1b2a133e6446"
          }
        ],
        "updatedAt": "2026-10-08T18:22:51.246933771Z"
      }
    },
    "facts": [
      {
        "a": "Agent harness",
        "b": "Agent harness",
        "name": "Kind"
      },
      {
        "a": "Cognition AI, Inc.",
        "b": "Paperclip Labs, Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://mcp.devin.ai/mcp",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Cognition's Platform Terms of Service",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "13",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "2026-06-30",
        "b": "2026-07-23",
        "name": "Terms last updated"
      },
      {
        "a": "2026-03-09",
        "b": "2026-07-23",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes, with an opt-out",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "none",
        "b": "99k stars, 60k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Paperclip scores 59 (C) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Devin or Paperclip?"
      },
      {
        "answer": "No open-source release is listed for Devin. Paperclip is open source (MIT).",
        "question": "Are Devin and Paperclip open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 72 against 64"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Paperclip loses 10 points for them"
        ],
        "goodFor": "A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.",
        "slug": "devin",
        "watchFor": "www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026"
      },
      {
        "aheadOn": [
          "Reliability, 66 against 30",
          "Agent ergonomics, 70 against 62",
          "Payments \u0026 pricing, 60 against 20",
          "Maintenance \u0026 community, 78 against 63"
        ],
        "also": [
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.",
        "slug": "paperclip",
        "watchFor": "`claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host"
      }
    ],
    "job": {
      "capability": "agent.multi-agent",
      "name": "Agent multi agent"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-devin.json",
        "title": "Aider vs Devin",
        "url": "https://www.anchorterminal.com/compare/aider-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-devin.json",
        "title": "Amp vs Devin",
        "url": "https://www.anchorterminal.com/compare/amp-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-devin.json",
        "title": "Claude Code vs Devin",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-devin.json",
        "title": "Cline vs Devin",
        "url": "https://www.anchorterminal.com/compare/cline-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-devin.json",
        "title": "Cursor CLI vs Devin",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi.json",
        "title": "Devin vs Pi",
        "url": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-gemini-cli.json",
        "title": "Devin vs Gemini CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-gemini-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-github-copilot-cli.json",
        "title": "Devin vs GitHub Copilot CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-github-copilot-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-goose.json",
        "title": "Devin vs goose",
        "url": "https://www.anchorterminal.com/compare/devin-vs-goose"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-kiro-cli.json",
        "title": "Devin vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-openai-codex.json",
        "title": "Devin vs OpenAI Codex",
        "url": "https://www.anchorterminal.com/compare/devin-vs-openai-codex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-opencode.json",
        "title": "Devin vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/devin-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-openhands.json",
        "title": "Devin vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/devin-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-prime-agent.json",
        "title": "Devin vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/devin-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-qwen-code.json",
        "title": "Devin vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/devin-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-paperclip.json",
        "title": "Amp vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/amp-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-paperclip.json",
        "title": "Claude Code vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-paperclip.json",
        "title": "Cline vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/cline-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip.json",
        "title": "Gemini CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip.json",
        "title": "GitHub Copilot CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/goose-vs-paperclip.json",
        "title": "goose vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/goose-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.json",
        "title": "Kiro CLI vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-paperclip.json",
        "title": "OpenCode vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openhands-vs-paperclip.json",
        "title": "OpenHands vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/openhands-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paperclip-vs-prime-agent.json",
        "title": "Paperclip vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/paperclip-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paperclip-vs-qwen-code.json",
        "title": "Paperclip vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/paperclip-vs-qwen-code"
      }
    ],
    "scores": [
      {
        "by": 36,
        "devin": 30,
        "edge": "paperclip",
        "key": "reliability",
        "name": "Reliability",
        "paperclip": 66,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "devin": 80,
        "edge": "paperclip",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "paperclip": 81,
        "weight": 13
      },
      {
        "by": 8,
        "devin": 62,
        "edge": "paperclip",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "paperclip": 70,
        "weight": 13
      },
      {
        "by": 8,
        "devin": 72,
        "edge": "devin",
        "key": "security",
        "name": "Security \u0026 auth",
        "paperclip": 64,
        "weight": 14
      },
      {
        "by": 40,
        "devin": 20,
        "edge": "paperclip",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "paperclip": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 15,
        "devin": 63,
        "edge": "paperclip",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "paperclip": 78,
        "weight": 7
      },
      {
        "by": 4,
        "devin": 69,
        "edge": "devin",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "paperclip": 65,
        "weight": 7
      }
    ],
    "summary": "Paperclip scores 59 (C) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth. Both do agent multi agent.",
    "verdicts": {
      "devin": "The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.",
      "paperclip": "Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/devin-vs-paperclip",
    "json": "https://www.anchorterminal.com/compare/devin-vs-paperclip.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/devin-vs-paperclip.md",
    "slim": "https://www.anchorterminal.com/compare/devin-vs-paperclip.min.md"
  },
  "markdown": "Paperclip scores 59 (C) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth. Both do agent multi agent.\n\n- Devin: grade C, 55.7/100, rank #447 of 629. Markdown https://www.anchorterminal.com/tools/devin.md · JSON https://www.anchorterminal.com/api/v1/tools/devin.json\n- Paperclip: grade C, 59/100, rank #390 of 629. Markdown https://www.anchorterminal.com/tools/paperclip.md · JSON https://www.anchorterminal.com/api/v1/tools/paperclip.json\n\n## Which one, for what\n\n### Devin (C)\n\nGood for: A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.\n\nAhead on:\n- Security \u0026 auth, 72 against 64\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Paperclip loses 10 points for them\n\nWatch for: www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026\n\n### Paperclip (C)\n\nGood for: Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.\n\nAhead on:\n- Reliability, 66 against 30\n- Agent ergonomics, 70 against 62\n- Payments \u0026 pricing, 60 against 20\n- Maintenance \u0026 community, 78 against 63\n\nAlso in its favour:\n- Free to start without a card\n- Open source\n\nWatch for: `claude_local` defaults `dangerouslySkipPermissions` to true and `codex_local` defaults to bypassing approvals and the sandbox, with agents running on the host\n\n\n## Score by category\n\n| Category | Weight | Devin | Paperclip | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 30 | 66 | Paperclip +36 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 80 | 81 | Paperclip +1 |\n| Agent ergonomics | 13% (16.2 this run) | 62 | 70 | Paperclip +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 72 | 64 | Devin +8 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 60 | Paperclip +40 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 63 | 78 | Paperclip +15 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 65 | Devin +4 |\n| Negative events | ≤15 | 0 | -10 | |\n| **Total** | | **55.7 · C** | **59 · C** | |\n\n## Facts side by side\n\n| Fact | Devin | Paperclip |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | Cognition AI, Inc. | Paperclip Labs, Inc. |\n| Hosted endpoint | `https://mcp.devin.ai/mcp` | no (local only) |\n| Transports | HTTP |  |\n| Auth | API key | OAuth or key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary service under Cognition's Platform Terms of Service | MIT |\n| Tools exposed | 13 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-10-05 |\n| Terms last updated | 2026-06-30 | 2026-07-23 |\n| Privacy policy last updated | 2026-03-09 | 2026-07-23 |\n| Customer content may train models | yes, with an opt-out | yes, with an opt-out |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | yes |\n| Popularity | none | 99k stars, 60k npm/wk |\n\n## Verdicts\n\n**Devin.** The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.\n\n**Paperclip.** Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.\n\n## Before you call either\n\n### Devin\n\n1. Use a `cog_` service-user key with the Member role. Legacy `apk_` keys fail against v3 and the MCP server with 401 or 403\n2. Set `max_acu_limit` on every session you create. Usage is metered by the work done and has no published unit rate\n3. Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again\n4. Enterprise keys and personal access tokens must send `X-Org-Id` to the MCP server. Organisation-scoped keys resolve it automatically\n5. Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026\n\n### Paperclip\n\n1. Set `PAPERCLIP_TELEMETRY_DISABLED=1` or `DO_NOT_TRACK=1` before the first start. Telemetry is on by default\n2. Set `dangerouslySkipPermissions` and `dangerouslyBypassApprovalsAndSandbox` to false on agents that read untrusted input, or run them in a sandbox provider\n3. Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there\n4. Use `--bind lan` or `--bind tailnet` at onboarding for anything beyond one machine. The default `local_trusted` mode treats every request as the board admin\n5. Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry\n\n## Questions\n\n### Which is better for AI agents, Devin or Paperclip?\n\nPaperclip scores 59 (C) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth.\n\n### Are Devin and Paperclip open source?\n\nNo open-source release is listed for Devin. Paperclip is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/devin-vs-paperclip.json, and with the fewest tokens: https://www.anchorterminal.com/compare/devin-vs-paperclip.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"devin\", \"b\": \"paperclip\"}`. From a terminal: `anchor compare devin paperclip`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/devin.json and https://www.anchorterminal.com/api/v1/tools/paperclip.json\n\n## Other comparisons with Devin or Paperclip\n\n- [Aider vs Devin](https://www.anchorterminal.com/compare/aider-vs-devin.md)\n- [Amp vs Devin](https://www.anchorterminal.com/compare/amp-vs-devin.md)\n- [Claude Code vs Devin](https://www.anchorterminal.com/compare/claude-code-vs-devin.md)\n- [Cline vs Devin](https://www.anchorterminal.com/compare/cline-vs-devin.md)\n- [Cursor CLI vs Devin](https://www.anchorterminal.com/compare/cursor-cli-vs-devin.md)\n- [Devin vs Pi](https://www.anchorterminal.com/compare/devin-vs-earendil-pi.md)\n- [Devin vs Gemini CLI](https://www.anchorterminal.com/compare/devin-vs-gemini-cli.md)\n- [Devin vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/devin-vs-github-copilot-cli.md)\n- [Devin vs goose](https://www.anchorterminal.com/compare/devin-vs-goose.md)\n- [Devin vs Kiro CLI](https://www.anchorterminal.com/compare/devin-vs-kiro-cli.md)\n- [Devin vs OpenAI Codex](https://www.anchorterminal.com/compare/devin-vs-openai-codex.md)\n- [Devin vs OpenCode](https://www.anchorterminal.com/compare/devin-vs-opencode.md)\n- [Devin vs OpenHands](https://www.anchorterminal.com/compare/devin-vs-openhands.md)\n- [Devin vs Prime Agent](https://www.anchorterminal.com/compare/devin-vs-prime-agent.md)\n- [Devin vs Qwen Code](https://www.anchorterminal.com/compare/devin-vs-qwen-code.md)\n- [Amp vs Paperclip](https://www.anchorterminal.com/compare/amp-vs-paperclip.md)\n- [Claude Code vs Paperclip](https://www.anchorterminal.com/compare/claude-code-vs-paperclip.md)\n- [Cline vs Paperclip](https://www.anchorterminal.com/compare/cline-vs-paperclip.md)\n- [Gemini CLI vs Paperclip](https://www.anchorterminal.com/compare/gemini-cli-vs-paperclip.md)\n- [GitHub Copilot CLI vs Paperclip](https://www.anchorterminal.com/compare/github-copilot-cli-vs-paperclip.md)\n- [goose vs Paperclip](https://www.anchorterminal.com/compare/goose-vs-paperclip.md)\n- [Kiro CLI vs Paperclip](https://www.anchorterminal.com/compare/kiro-cli-vs-paperclip.md)\n- [OpenCode vs Paperclip](https://www.anchorterminal.com/compare/opencode-vs-paperclip.md)\n- [OpenHands vs Paperclip](https://www.anchorterminal.com/compare/openhands-vs-paperclip.md)\n- [Paperclip vs Prime Agent](https://www.anchorterminal.com/compare/paperclip-vs-prime-agent.md)\n- [Paperclip vs Qwen Code](https://www.anchorterminal.com/compare/paperclip-vs-qwen-code.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Devin vs Paperclip",
        "url": ""
      }
    ],
    "description": "Paperclip scores 59 (C) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth. Both do agent multi agent. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Devin C 55.7",
      "Paperclip C 59",
      "scores"
    ],
    "h1": "Devin vs Paperclip",
    "image": "https://www.anchorterminal.com/assets/og/compare-devin-vs-paperclip.png",
    "path": "/compare/devin-vs-paperclip",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Devin vs Paperclip for AI agents, C 55.7 vs C 59 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/devin-vs-paperclip"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 630
  },
  "version": 1
}
